Make some parameters optional in REST API POST

Viewed 153

I making a Web App and Web API. I have done this in my web API

public void Post([FromBody] Expense expense)
    {
        string commandText = "INSERT INTO EXPENSE (Date, Description,Rate, BranchId) VALUES " +
                            " (@Date, @Description, @Rate, @BranchId)";

        string connStr = System.Configuration.ConfigurationManager.ConnectionStrings["connectionString"].ConnectionString;

        using (SqlConnection connection = new SqlConnection(connStr))
        {
            using (SqlCommand command = new SqlCommand(commandText, connection))
            {

                connection.Open();
                command.CommandType = CommandType.Text;
                command.Parameters.AddWithValue("@Date", (DateTime)expense.Date);
                command.Parameters.AddWithValue("@Description", (string)expense.Description);
                command.Parameters.AddWithValue("@Rate", (Decimal)expense.Rate);
                command.Parameters.AddWithValue("@BranchId", (int)expense.BranchId);

                int rowInserted = command.ExecuteNonQuery();
                connection.Close();
            }
        }
    }

When I send all parameters to my Web API from my web app then it works well but Rate and Branch Id are optional. If I don't send BranchId and Rate then it give me error "POST/ 405 (Method Not Allowed)". What can I do to make parameters optional. Input comes in json format.

ManageExpense() {


    //object is to post data in JSON format to API
    let object: any = {};

    object.Date = this.Expense.Date;
    object.Description = this.Expense.Description;
    object.Rate = this.Expense.Rate;
    object.BranchId = this.Expense.Branch.Id;

    this.httpService.post('https://localhost:44373/api/add', object)
        .then(res => {
            console.debug(res);
        });
    return this.router.navigateToRoute("home");
}

Even on front end also I am getting error , if I am not sending all parameters

used to execute inline script because it violates the following Content Security Policy directive: "default-src 'self'". Either the 'unsafe-inline' keyword, a hash ('sha256-ThhI8UaSFEbbl6cISiZpnJ4Z44uNSq2tPKgyRTD3LyU='), or a nonce ('nonce-...') is required to enable inline execution. Note also that 'script-src' was not explicitly set, so 'default-src' is used as a fallback.

0 Answers
Related